Live data from Hacker News

Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

ptsecurity.com

21–30 of 56 posts

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#21
post #20
post #19

Earlier quoted context omitted.

Good point. Some payment processors credit sellers with just one confirmation. But it can still take several minutes, or more if your wallet client doesn't add enough fee. Also, with Bitcoin price so high, fees are absurd for small transactions. That's the real problem. For large transactions, on the other hand, Bitcoin is faster than wire transfer. I can move thousands of USD in a few hours, anonymously through a mi…

Last month I moved £10,000 between two UK banks and it settled in 3 seconds. Fees were £0.00. I could have moved more for exactly the same fee of free.

What mechanism?

Moving funds internationally, in my experience, has sometimes taken days.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#22
post #16
post #10

Earlier quoted context omitted.

Maybe it's time for SSMS? The extra S being for secure, of course. Something encrypted and requiring authentication would be good - and maybe (tangentially related) not letting just anyone transfer your phone number to a new phone contract. That should require ID and some level of additional authentication. It's like the whole thing is a house of cards. I'm half amazed that it works as well as it does and isn't explo…

Better 2FA exists. We still need better identity authentication. Copied passports, phone numbers, and email all have problems. There are government initiatives (in the US it seems to be NSTIC and login.gov). This should be opened up and made international. It seems that login.gov is already an OpenID identity provider. So only marketing is left. Next to login with Facebook and Google, there should be a "login with Go…

I'd like to see something done in that area. Unfortunately, I'm not sure how politically feasible login.gov is. No, I know it exists and is technically possible - but we have people, a lot of them, who are very much against government tracking. We have people who think the census should be illegal and will claim it is a conspiracy when you point out it is an enumerated responsibility listed in the constitution.

We have religious people who will claim it is the foretold sign of the beast and forbid use by their congregation.

So, as you say, it is going to need some marketing. Those same people will often give their information to Facebook, by the way. Once it's from the government, I bet there is blowback. When it was announced, even comments on HN and Slashdot were immediately against the idea.

But, yeah, you're right. It's going to need government involvement, I'm just not sure that is a realistic hope. I also don't have a better solution.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#23
post #21
post #20

Earlier quoted context omitted.

Last month I moved £10,000 between two UK banks and it settled in 3 seconds. Fees were £0.00. I could have moved more for exactly the same fee of free.

What mechanism? Moving funds internationally, in my experience, has sometimes taken days.

It will be using faster payments[1] which allows up to £250,000 to be moved between UK accounts without any fees. For how long it takes I'm used to seeing "within 2 hours" claimed but in practice it's instantaneous.

[1] https://en.m.wikipedia.org/wiki/Faster_Payments_Service

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#24
post #23
post #21

Earlier quoted context omitted.

What mechanism? Moving funds internationally, in my experience, has sometimes taken days.

It will be using faster payments[1] which allows up to £250,000 to be moved between UK accounts without any fees. For how long it takes I'm used to seeing "within 2 hours" claimed but in practice it's instantaneous. [1] https://en.m.wikipedia.org/wiki/Faster_Payments_Service

OK, what about UK to Brazil? Or UK to Russia?

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#25
post #21
post #20

Earlier quoted context omitted.

Last month I moved £10,000 between two UK banks and it settled in 3 seconds. Fees were £0.00. I could have moved more for exactly the same fee of free.

What mechanism? Moving funds internationally, in my experience, has sometimes taken days.

I routinely move funds internationally using the old-fashioned mechanism called "wire transfer" which for my particular case, is settled in hours and has zero fee.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#29
post #27

Mobile phones should be used as a hot wallet storing small amount for convenience. The rest of the bulk should be on a https://trezor.io/

Or a paper wallet, which is free, although it involves jumping through some extra hoops.

Here's the steps the steps commonly advised for Ethereum (also works for storing ERC-20 tokens):

Look up "My Ether Wallet" (be extremely paranoid and treble check the URL so you don't get scammed with a fake duplicate website). If you follow the steps below, your wallet is as hack-proof as a Nano/Trezor (just store the paper wallet securely, because it's the same as cash when the wallet is loaded with Ether).

1. Create an offline MEW wallet, on a secure PC not connected to the internet (e.g. boot Linux ISO from a read only DVD)

2. Print out the wallet details (will have the private key, a QR code for the wallet address, and another QR code for the private key).

3. Send a small amount of Ether to test that you have the correct details (if you bought on Coinbase, use their app to scan the QR code of the paper wallet). The Ether should show up in the wallet within a few seconds (use etherscan.io to check your new address).

4. If the test went ok, send the remaining Ether from Coinbase -> MEW.

5. (Optional) Backup a digital copy of the MEW wallet on a clean USB, that you exclusively use for that purpose. Store the wallet details in a password manager on the USB, e.g. KeePass, Keeweb, (any open source password manager that is kdbx compliant). This is convenient for when you wish to do transfers. Make sure you don't accidentally copy these details to another PC, upload them online somehow, etc.

Re: Vulnerabilities in mobile networks opens Bitcoin wallets to hackers

#30
post #7

Slightly less exciting TLDR: as many of you already know, SMS isn't a good second factor for auth. That includes entrusting your Bitcoin wallet's private keys to a company using SMS for 2FA. Let's mention "cryptocurrency" as well to show up in more news alerts.

Thanks so much for that TLDR :)
Post reply on HN